
Development updates and some product evolution details.
Core
- Finished integrating to Beta status native Quantum Resistant Accounts, native ‘authorization group’ accounts, and Associate Chains.
- Another feature is that an account can be flagged as ‘protected’, such that it can only receive payments if the owner co-signs the transaction. This can be done by wrapping the transaction in an authorization proposal, which is automatically forwarded to a proposal pool, where prospective co-signers can inspect and sign the transaction. An account can e.g. operate normally on an Associate Chain, while being protected on Groot. Quantum Resistant accounts work across Associate Chain connection points.
- Completed HTTP endpoints for waiting for transaction status, including finality, via push events.
- Added a subscription endpoint for Sophia Contract Events.
- Refined the State Channels benchmark suite to use agentive-style auto-signing and found some performance improvements.
- Prototyped ASN.1-driven serialization support for better portability. Improved CLI support for account status and configuration browsing.
- Indexing Plugin is now prepared to go live serving the Gajumaru Explorer, with assistance from summer intern Alex Hinde. This also serves as a practical demonstration of how to write node plugins with custom OpenAPI-driven HTTP endpoints — a core part of our concept of Utility Nodes for business integration.
GajuMobile
- Android serialization libraries, test suites and platform security examination.
GajuMining
- New Rewards system is finalised and merged. It will be released as soon as the new dashboard is ready.
- New Dashboard: we prepared the following new widgets:
update Outreach Tier Widget with Free License Tier Widget
Create Progress Bar component
We dropped the support for details for pre-mining era. At this point we are finalising the layout of the dashboard. - Third party sellers dashboard is polished and finalised.
- Some refactoring of the shop UI to be released soon: we show resend countdowns for verification codes, added a remove promo code action to cart, mobile view of the cart.
- Payment providers now come with logos for better UX. The cart has a feedback animation when adding items with quick-add feedback panel. We added steppers so users are aware what happens next and where there are in the checkout process.
- When users open the downloads page on different OS – we detect the OS to provide the appropriate links. Now we added a small page for mobile devices.
- Small polishes, bug fixes, introduced a few new audit and security tools in the pipeline
GajuAuth
GajuAuth is a platform connecting OAuth 2.0 applications with GRIDS sovereign identities. Users and administrators authenticate through cryptographic public-key challenges—without passwords—while organizations gain centralized control over clients, identities, tokens, signing keys, auditing, and operational health.
So far, we have delivered authorization-code and refresh-token flows, PKCE, JWT and opaque tokens, revocation, introspection, UserInfo, JWKS publishing, and signing-key rotation. Recent work strengthened the platform with PAR, JAR, JARM, DPoP, resource indicators, rich authorization requests, step-up authentication, rate limiting, token diagnostics, security-focused defaults, polished administration tools, automated quality checks, and production release packaging.
Supporting applications are being built to seamlessly integrate with GajuAuth, outlined below.
GajuRegistry
We’ve built a resource server that stores user registry profiles and provides scoped OAuth2-protected APIs for names, avatars, emails, phone numbers, and addresses. It integrates with GajuAuth through token introspection or JWT validation, with support for PAR, JAR, JARM, and DPoP. The application includes admin interfaces for registries, administrators, resource clients, JWT audiences, scopes, audit logs, token diagnostics, and metrics. We also added rate limiting, trusted-proxy handling, security validation, OpenAPI documentation, production releases, database migrations, and automated test coverage. We synchronized the application with newer GajuAuth capabilities and strengthened its OAuth and DPoP support.
GajuPassport
GajuPassport has evolved into a polished identity and consent portal that allows users to securely sign in with GajuAuth, view and manage identity information stored in GajuRegistry, and choose which profile fields may be shared with connected services. The project now includes clear handling of authorized and restricted information, avatar support, transparent protocol activity logs, reliable login and error flows, and a refined, responsive interface. Behind the scenes, the authentication integration has been strengthened with modern OAuth 2.0 security features, comprehensive automated testing, flexible production configuration, database migration support, and a streamlined release process that packages the application for deployment as a production-ready archive.
GajuOAuth2 Demo Portal
We’ve created a responsive technical guide to the Gaju OAuth2 ecosystem. It explains how the resource owner, GajuPassport, GajuAuth, and GajuRegistry work together—from authentication and consent through token issuance, validation, and scoped data access. Dedicated participant pages clarify responsibilities, trust boundaries, security guarantees, and the principle that private keys remain under the owner’s control. The application is also packaged for configurable production deployment.
Interested in building early on Gajumaru? Learn more about Gajumaru blockchain.
Want to mine Gajus? Early miners only have until 2027 before protected mining ends.